Who the controller is
The controller of your personal data is Treto Group s.r.o., company registration number (IČO) 29955700, with its registered office at Kubelíkova 1258/43, Žižkov, 130 00 Praha 3, Czech Republic, registered in the Commercial Register kept by the Municipal Court in Prague, section C, insert 455075.
For anything concerning personal data, reach us at privacy@treto.cz. We have not appointed a Data Protection Officer: we are not a public authority, we do not carry out large-scale systematic monitoring of people, and we do not process special categories of data on a large scale, so the GDPR does not require one.
What this document is for
It describes what data we process about you when you use Treto, why, for how long, and who we pass it to. We have tried to write it so it can be read, rather than so it satisfies a form.
Its companion, the Cookies Policy, covers what is stored on your own device.
What we process and why
| What we process | What for | Legal basis |
|---|---|---|
| Email, phone, username, password (stored hashed) | Running your account, signing in, password reset | Performance of a contract |
| Name, email and profile picture from a Google account | Signing in with Google, if you choose it | Performance of a contract |
| Phone number verification | Reducing the number of fake accounts | Legitimate interest |
| Profile: photo, description, languages, service area | Showing your profile to other users | Performance of a contract |
| A professional's declaration of whether they trade | Showing whether they are a business or a private individual — required by consumer law | Legal obligation |
| Services: title, description, price, duration, photos, location | Publishing the listing in the catalogue | Performance of a contract |
| Professional portfolio | Showing examples of work | Performance of a contract |
| Bookings: time, service, status, no-show flag | Arranging and recording the booking | Performance of a contract |
| Chat messages | Communication between client and professional | Performance of a contract |
| Detection of contact details in a message — telephone numbers, email addresses, links — and a note of where in the text they stand | Hiding them from the recipient until a booking between you is confirmed. We do it so that an arrangement is not carried off Treto, where it leaves no record either side can rely on in a dispute, and so that contact details are exchanged after a booking rather than instead of one; and to recognise repeated attempts, which we pass to moderation | Legitimate interest |
| Whether and when a message was read | Marking a conversation as read, on every device you are signed in on, and showing the other side that their message arrived | Performance of a contract |
| Reviews and replies to them | Showing others' experience | Performance of a contract; legitimate interest for display |
| The licence declaration made when publishing a service | Evidence that the professional declared holding the required licences | Legitimate interest |
| Reports of unlawful content | Assessing the report and moderating | Legal obligation, legitimate interest |
| The list of users you have blocked | Stopping messages and bookings between you | Legitimate interest |
| A fingerprint of a blocked account's email and phone | Stopping a block from being undone by registering again at once | Legitimate interest |
| A device fingerprint (from IP address and browser) | Recognising a sign-in from an unknown device and warning you by email | Legitimate interest |
| "Last online" | Showing your availability to the other side; can be turned off in settings | Legitimate interest |
| Saved favourite services | Keeping your list of favourites | Performance of a contract |
| IP address, device technical data, server logs | Operation, security, debugging | Legitimate interest |
We do not rely on consent as a legal basis — there are no marketing mailings, no analytics and no advertising tools. If that changes, we will ask for consent separately, and it will be withdrawable at any time.
Where the data comes from
Most of it you give us directly — registering, filling in a profile, publishing a service, making a booking or writing a message.
If you choose to sign in with Google, Google gives us your name, email address and profile picture.
Some of it arises automatically from using the service: your IP address in server logs, technical data about your device, the state of your bookings.
Protection against automated attacks
To protect our platform from bots and automated abuse, we use Google reCAPTCHA Enterprise. This service analyses user behaviour in the background and does not require any interaction from you.
The use of reCAPTCHA Enterprise is subject to Google's Privacy Policy and Terms of Service.
reCAPTCHA loads only at the moment you submit the sign-in form, the registration form, the password reset form, or a report of unlawful content. It does not load while you browse the catalogue.
Who we pass data to
We pass on only what is necessary, and only to these processors:
| To whom | For what | Where |
|---|---|---|
| Hetzner Online GmbH | Running the servers, the database and stored photographs | Helsinki, Finland |
| Mailgun Technologies | Sending email — notices about bookings, notices that a message is waiting for you, password resets and security warnings. The text of a message is never put in an email: a letter is read on a lock screen, forwarded and kept long after the conversation is gone, so it says only who wrote and how many times | European Union |
| SMSmanager | Sending verification SMS | Czech Republic |
| Functional Software (Sentry) | Application error reporting | Germany |
| Seznam.cz a.s. (Mapy.com) | Displaying maps and searching addresses | Czech Republic |
| Google Ireland / Google LLC | reCAPTCHA Enterprise | See below |
| Google Ireland / Google LLC | Automated check of text before publication (Cloud Natural Language) | See below |
| Google Ireland / Google LLC | Automated check of images before publication (Cloud Vision) | See below |
We do not sell data and do not pass it on for anyone else's marketing.
We may in addition disclose it to public authorities where the law requires, and to our legal or tax advisers where necessary.
One special case — the other side of a booking. When you book a service, we give the professional what they need to deliver it: your name, contact details and the booking particulars. In respect of that data the professional becomes a separate controller, responsible for how they handle it from then on.
Transfers outside the European Union
Our infrastructure is entirely within the European Union. The exceptions are three Google services: reCAPTCHA Enterprise, Cloud Natural Language for checking text and Cloud Vision for checking images. The assessment runs on Google's servers, which may be outside the EU, in particular in the United States.
Read that plainly: your service description, your review text and every photograph you upload — the profile picture included — pass through a Google server before they are published. Private chat messages are not sent there.
That transfer relies on the standard contractual clauses approved by the European Commission, which Google uses as its safeguard for transferred data.
How long we keep it
| What | How long |
|---|---|
| Account data | While the account exists. On an erasure request the account is anonymised at once; what is left of it — the records below — ages out within three years |
| Chat messages | 6 months from sending |
| The contact-detection note on a message | As long as the message it belongs to. The message itself is never altered by it |
| Reviews | Stay published; detached from the account when it is deleted |
| Booking history | 3 years — the limitation period |
| Archived services | 3 years from archiving, together with their bookings |
| Licence declarations | While the service exists, and 3 years after |
| A block on another user | While the block lasts; unblocking deletes the record |
| Device fingerprints | The last 20 devices; older ones are overwritten by newer |
| A fingerprint of a blocked account's email and phone | While the block lasts, and never longer than 3 years. Deleting it does not lift the block on the account — it only ends our ability to recognise the same email or phone at a new registration |
| Server and error logs | 90 days |
| Records with tax significance | For the period tax law requires |
Your rights
In relation to your data you have the right:
- of access — to know what we process about you and to get a copy,
- to rectification — to have inaccurate data corrected; most of it you can correct yourself in the settings,
- to erasure — to have data deleted where no ground for continued processing remains,
- to restriction of processing — for instance while we examine an objection you raised,
- to portability — to receive your data in a machine-readable format,
- to object to processing based on legitimate interest.
Exercise them at privacy@treto.cz. We reply within one month; for complex requests we may extend that by a further two months, and will tell you if we do.
We may need to verify your identity before acting on a request — so that we do not hand your data to someone else.
If your account is blocked, the interface will not show you your data — the only page left is the one giving the reason and the route to an appeal. That does not remove your right of access: write to privacy@treto.cz and you will get it like anyone else.
On blocking we confirm only what concerns you. Who you have blocked is your own data and we will tell you on request. It does not work the other way round: we will confirm that a block exists, but not who is behind it. A block is there to shield someone from unwanted contact, and naming them would undo that protection — under Article 15(4) GDPR the right of access must not adversely affect the rights and freedoms of others.
Some data cannot be deleted on request. That applies in particular to records we must keep for tax purposes, and to reviews, which are another user's experience rather than your content — on account deletion we detach them from your identity, but we do not republish them under anyone else's name.
What an erasure actually does. Your email, phone, name, photo and everything else that identifies you are cleared straight away, and your username stops resolving — we do not keep a redirect from it. Reviews you wrote stay published without your name: they describe somebody else's work, and removing them would quietly edit that person's record. Reviews about you stop being shown. Bookings are kept for three years, the limitation period, and whatever remains is deleted once it runs out.
The same goes for the archive of deleted services. When you delete a service it disappears from the catalogue and from your own list at once, but we keep the record of it, and of the bookings that belonged to it, for three years in case a dispute arises later. Article 17(3)(e) GDPR allows this — the establishment, exercise or defence of legal claims.
Automated decision-making
We do not take decisions about you based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
We do use automated means as an aid in content moderation and in protecting against abuse. Where that leads to a measure against you, you will be told — including that automated means were used — and you have the right to human review. The procedure is described in the Terms of Service.
Children
Treto is for people aged 18 and over and we do not knowingly process children's data. If we find that we have obtained such data, we delete it. If you believe we hold data on someone under 18, write to privacy@treto.cz.
Security
Traffic between your browser and our servers is encrypted. Passwords are not stored in readable form. Access to data is limited to those who need it. The servers are in a data centre within the European Union.
No measure is absolute. If you suspect someone else has reached your account, change your password and tell us.
Changes to this policy
This document describes what actually happens, not a general intention — so it changes whenever the processing changes. We give notice of substantive changes in advance. The version number and effective date are in the header.
Contact and complaints
Questions and requests go to privacy@treto.cz; anything else to the addresses on the Contacts page.
If you believe our processing of your data breaches the law, you have the right to lodge a complaint with the supervisory authority:
Úřad pro ochranu osobních údajů Pplk. Sochora 27, 170 00 Prague 7, Czech Republic uoou.gov.cz
We would be glad if you came to us first — most things get resolved faster that way.



